Cyfin & CyBlock Terms Glossary — Key Terms Explained
Applies to: Cyfin and CyBlock · Plain-language definitions of the terms used across the products and their reports.
This glossary defines the terms customers most often ask about — the reporting metrics, the categorization concepts, and the product features that shape what you see. Unless noted, a term applies to both Cyfin and CyBlock. For the full report list, see the Report Glossary; for the full category list, see the Category Glossary.
Reporting metrics
Session — A period of continuous user activity with a single application/site, reconstructed from the log. Sessions rebuild scattered proxy/firewall connection records into readable browsing events and filter out non-human background traffic (OS updates, telemetry, ad trackers), so a report reflects what a person actually did rather than raw log volume. Session count is the primary metric in high-level reports.
Session Duration — The elapsed time from the first to the last record within a session, shown as HH:MM:SS — meaningful active time, not raw connection time. Available only in the session reports. It replaces the retired Time Online metric.
Session Thresholds — The conditions activity must meet to be recorded as a session (for example, a minimum duration, a minimum number of hits, an inactivity timeout, and a maximum duration). These are Wavecrest-managed settings and should not be changed without Wavecrest’s assistance — please contact Technical Support before adjusting them.
Sessions % — A given application/site’s or category’s share of all sessions, shown as a number and a classification-colored bar.
Session Duration % — A given application/site’s or category’s share of total reporting-period time. A site with few sessions can still show a high duration % if those sessions were long.
Hit — A single log record. One page load generates many hits (images, scripts, stylesheets, and background requests). Hits are the raw material sessions are built from and appear at the deepest drill-down level, not as a headline metric. In the hit-based reports (everything outside the session reports), activity is measured in hits and bytes.
Bytes — The volume of data transferred, shown in KB or MB.
Denied Request — A request blocked by your proxy or firewall before it reached its destination. A non-zero count means access to blocked content was attempted during the period or session.
What happened to Visits and Time Online?
Both metrics have been retired. Visits have been upgraded to Sessions, which capture a user’s continuous engagement with a site rather than a single-interaction count — a clearer, more accurate picture in today’s dynamic web. Time Online has been replaced by Session Duration, which is available in the session reports. The hit-based reports now measure activity by Hits and Bytes and no longer show Visits or Time Online. This reflects how the web changed, not a correction of past reporting.
Categorization terms
Category — The content category assigned to a website (e.g., Video Streaming, Gambling, News), drawn from the shared Wavecrest URL List. See the Category Glossary for the full list and definitions.
Classification — A label — Acceptable, Unacceptable, or Neutral — that a customer assigns to each category to reflect their company policy. It appears in reports (color-coded: green / orange / gray) to give the report consumer a policy-based read on activity. Classification affects reporting only; it does not by itself block anything.
Custom Category — A category you create yourself (beyond the 70+ standard categories) and populate with URLs of your choosing — for example, to track intranet sites or to group a set of sites for filtering. Custom category and URL changes override future Wavecrest URL List downloads.
OtherWise — An optional program Cyfin and CyBlock customers can opt into to help improve categorization. When enabled, domains that are missing a category or tag are forwarded to Wavecrest’s cloud list server for review and analysis. Only the domain that needs review is sent — no other information — and the result is better list quality for everyone.
Acceptable Use Policy (AUP) — Your organization’s own policy defining acceptable web use. Cyfin and CyBlock help you monitor and enforce your AUP through their customization features (categories, classifications, and — in CyBlock — filtering).
Users and groups
User ID — The network login identifier used to attribute activity to an individual across all reports (e.g., firstname.lastname). Cyfin reads IDs from the log; CyBlock obtains an ID via NTLM when creating a proxy connection.
Groups and IDs — The tree of users and groups the product uses to organize activity. You can build it manually or sync it from Active Directory (importing your existing group and ID structure). Reporting and policies can then be organized by group.
Ungrouped IDs — Where an ID lands when it isn’t matched to an entry in your Groups and IDs tree. When Cyfin reads an ID from the log — or CyBlock receives one via NTLM — that ID is checked against the tree; if it doesn’t match a defined ID, it’s placed in Ungrouped IDs. If you never build a tree or sync from Active Directory, all IDs go into Ungrouped IDs by default. (If you’re running a report and can’t find the IDs you expect, this is often why — they’re sitting in Ungrouped IDs because the tree hasn’t been built or synced.)
Product features
Coaching (CyBlock only) — A filtering option that, when enabled, adds an override link to the block message shown when an employee reaches a blocked site. The employee can choose to bypass the block and continue to the site — and that action is logged, so the organization can later verify whether the visit was legitimate. Customers use coaching as a safety valve in case a valid site is blocked and a user genuinely needs access.
Ingestion — The process of loading raw proxy/firewall log data into the product for a given user and period. Reporting begins after ingestion completes. By default, known non-human domains (ad trackers, telemetry, OS updates, endpoint security) are excluded during ingestion; this can be disabled if a full traffic record is needed.
Application / Web Site (App/Site) — A recognized web service that groups all its related domains under one friendly name (e.g., fbcdn.com rolls up under “Facebook”), keeping reports readable for non-technical reviewers.